Description
Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a through <= 2.6.0.
Published: 2025-08-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect privilege assignment flaw exists in the DELUCKS SEO WordPress plugin. The vulnerability allows a user with insufficient privileges to gain higher level capabilities, effectively enabling an attacker to perform actions normally reserved for administrators. The fault aligns with CWE‑266 and could lead to full control over the WordPress site, compromising data confidentiality, integrity, and availability.

Affected Systems

The flaw is present in all releases of the DELUCKS SEO plugin from the earliest version through version 2.6.0. Any WordPress site that has installed this plugin and has not upgraded past 2.6.0 is potentially affected. The plugin functions within the standard WordPress environment, so any site using this plugin is at risk.

Risk and Exploitability

The CVSS score of 8.8 denotes a high severity vulnerability, while the EPSS score of less than 1% indicates a low likelihood of current exploitation. The vulnerability is not represented in the CISA KEV catalog. Based on the description, it is inferred that the attack vector likely involves a normal user interacting with the plugin’s administrative interface or issuing a crafted request that triggers the privilege misassignment. An attacker would need authenticated access to the site, but the exploitation path does not require remote code execution or other advanced privileges beyond those offered by the plugin’s improper access controls.

Generated by OpenCVE AI on May 1, 2026 at 06:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest version of the DELUCKS SEO plugin, which includes the privilege assignment fix.
  • Review and reset user roles after the update to ensure only intended roles retain elevated privileges; remove any unnecessary capabilities added by previous versions.
  • If custom code modifications were made to the plugin, revert those changes or apply the vendor‑supplied patch to the modified files.

Generated by OpenCVE AI on May 1, 2026 at 06:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-28150 Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO allows Privilege Escalation. This issue affects DELUCKS SEO: from n/a through 2.6.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO allows Privilege Escalation. This issue affects DELUCKS SEO: from n/a through 2.6.0. Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a through <= 2.6.0.
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sun, 24 Aug 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Delucks
Delucks delucks Seo
Wordpress
Wordpress wordpress
Vendors & Products Delucks
Delucks delucks Seo
Wordpress
Wordpress wordpress

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO allows Privilege Escalation. This issue affects DELUCKS SEO: from n/a through 2.6.0.
Title WordPress DELUCKS SEO Plugin <= 2.6.0 - Privilege Escalation Vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Delucks Delucks Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:53.141Z

Reserved: 2025-05-15T18:02:16.098Z

Link: CVE-2025-48165

cve-icon Vulnrichment

Updated: 2025-08-20T15:20:16.717Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:32.527

Modified: 2026-04-23T15:30:55.023

Link: CVE-2025-48165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T06:45:11Z

Weaknesses